Adaptive Identity Provider Authentication Context Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face repetitive and time-consuming multi-factor authentication (MFA) prompts when accessing multiple applications with the same identity provider, leading to poor human-computer interaction and increased computing resources and network bandwidth usage.
Innovation Solution
An identity provider (IDP) monitors user patterns and context to determine a low-risk scenario, allowing for reduced MFA prompts by using one-factor authentication based on conditions such as consistent IP address usage, authentication timing, and device location, thereby minimizing repetitive authentication requests.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multi-factor authentication is implemented for all application access requests, then security is improved, but user experience deteriorates due to repetitive authentication prompts
Solution Approach 1:
The patent applies local quality by differentiating authentication requirements based on the specific access context. Instead of applying uniform MFA to all requests, the system evaluates local characteristics such as client device trustworthiness, user behavior patterns, and access timing to determine whether MFA is needed, thereby improving user experience without compromising security for low-risk scenarios
Solution Approach 2:
The patent implements dynamics by making the authentication policy adaptive and context-dependent. The system dynamically adjusts authentication requirements based on real-time evaluation of risk factors, including user behavior analysis, device reputation, and access patterns, allowing the authentication mechanism to flex between strict MFA and relaxed single-factor authentication
2Reliability
If multi-factor authentication is required for every application access, then security verification is thorough, but access time increases significantly
Solution Approach 1:
The patent applies preliminary action by pre-establishing user profiles and device trust assessments before actual access occurs. The system continuously monitors and stores user behavior patterns, device reputation data, and authentication history, so that when access requests arrive, the system can quickly evaluate pre-collected data to determine authentication requirements without requiring real-time MFA for low-risk scenarios
Solution Approach 2:
The patent utilizes parameter changes by adjusting authentication stringency based on risk parameter evaluation. The system monitors parameters such as access timing, device location, user behavior patterns, and authentication frequency, and changes the authentication parameter from strict MFA to relaxed single-factor authentication when parameters indicate low risk, thereby reducing access time while maintaining security
3Reliability
If authentication context is stored per application, then application-specific security is maintained, but context cannot be shared across applications
Solution Approach 1:
The patent applies universality by implementing a unified authentication context storage mechanism that serves multiple applications simultaneously. Instead of maintaining separate context storage for each application, the system creates a shared user profile and authentication history database that all applications can access, enabling context sharing while maintaining security through centralized management
Solution Approach 2:
The patent uses an intermediary approach by introducing a centralized authentication service or user profile database that mediates between applications and the authentication system. This intermediary layer allows applications to access shared authentication context without direct peer-to-peer communication, maintaining security boundaries while enabling context sharing across application boundaries
Data Source
AI summary
Described embodiments provide systems, methods, non-transitory computer-readable medium for initiating one-factor or multi-factor authentication. A device comprising one or more processors and coupled to memory. The device can receive a request to authenticate a user to enable access to an application by the user. The request can originate from an Internet Protocol (IP) address external to a network hosting the application. The device can determine that a previous request to authenticate the user originated from the IP address and was approved based on successful completion of multi-factor authentication by the user. The device can provide, responsive to the determination, the user with access to the application using one-factor authentication instead of the multi-factor authentication.


